Описание
Security update for python-urllib3
This update for python-urllib3 fixes the following issue
- CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267).
Список пакетов
Image SLES12-SP5-Azure-BYOS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-HPC-BYOS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-HPC-On-Demand
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-SAP-BYOS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-SAP-On-Demand
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-Standard-On-Demand
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-EC2-BYOS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-EC2-ECS-On-Demand
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-EC2-On-Demand
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-EC2-SAP-BYOS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-EC2-SAP-On-Demand
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-GCE-BYOS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-GCE-On-Demand
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-GCE-SAP-BYOS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-GCE-SAP-On-Demand
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
SUSE Linux Enterprise Module for Public Cloud 12
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
SUSE Linux Enterprise Server 12 SP5-LTSS
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
python-urllib3-1.25.10-3.51.1
python3-urllib3-1.25.10-3.51.1
Ссылки
- Link for SUSE-SU-2026:2065-1
- E-Mail link for SUSE-SU-2026:2065-1
- SUSE Security Ratings
- SUSE Bug 1265267
- SUSE CVE CVE-2026-44431 page
Описание
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
Затронутые продукты
Image SLES12-SP5-Azure-BYOS:python-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-BYOS:python3-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-HPC-BYOS:python-urllib3-1.25.10-3.51.1
Image SLES12-SP5-Azure-HPC-BYOS:python3-urllib3-1.25.10-3.51.1
Ссылки
- CVE-2026-44431
- SUSE Bug 1265267